search for: sambapwdcanchange

Displaying 20 results from an estimated 291 matches for "sambapwdcanchange".

2005 Nov 17
0
Replication errors with LDAP and problems with NT machines
.../home/netlogon/%a [profiles] path = /home/profiles/%a writeable = yes browsable = no force create mode = 0644 force directory mode = 0755 3. Replication log ######################## /var/lib/ldap/replica/hera.elysion.lan:389.rej ######################## ERROR: No such attribute: modify/delete: sambaPwdCanChange: no such value replica: hera.elysion.lan:389 time: 1132047279.0 dn: uid=eurydice$,ou=Computers,dc=elysion,dc=lan changetype: modify delete: sambaPwdCanChange sambaPwdCanChange: 1132045192 - add: sambaPwdCanChange sambaPwdCanChange: 1132047279 - delete: sambaLMPassword sambaLMPassword: 60F9BE525098F...
2004 Feb 13
0
strange error: modify/delete: sambaPwdCanChange: no such value (Success)
...sdb/pdb_ldap.c:init_ldap_from_sam(769) init_ldap_from_sam: Setting entry for user: hasp$ [2004/02/14 00:03:47, 1] passdb/pdb_ldap.c:ldapsam_modify_entry(1217) ldapsam_modify_entry: Failed to modify user dn= cn=hasp,ou=Computers,dc=komi,dc=mts,dc=ru with: No such attribute modify/delete: sambaPwdCanChange: no such value [2004/02/14 00:03:47, 0] passdb/pdb_ldap.c:ldapsam_update_sam_account(1417) ldapsam_update_sam_account: failed to modify user with uid = hasp$, error: modify/delete: sambaPwdCanChange: no such value ( Success) [2004/02/14 00:05:05, 2] smbd/server.c:exit_server(558) Closing connec...
2004 Mar 15
1
smbpasswd trying to add instead of replace attribut
...delete and add again), pls see the "MOD" from log file (from different domain) : UNSUCESSFULL Mar 15 17:10:53 hurricane slapd[27056]: conn=29489 op=1 MOD dn="uid=pwreka,ou=people,ou=purwakarta,dc=indorama,dc=com" Mar 15 17:10:53 hurricane slapd[27056]: conn=29489 op=1 MOD attr=sambaPwdCanChange sambaPwdCanChange sambaPwdMustChange samb aPwdMustChange sambaLMPassword sambaNTPassword sambaPwdLastSet sambaPwdLastSet Mar 15 17:10:53 hurricane slapd[27056]: Entry (uid=pwreka,ou=people,ou=purwakarta,dc=indorama,dc=com), attribute 'sambaLMPas sword' cannot have multiple values Mar 15 17:...
2006 Mar 09
1
changing password on samba bdc
...SRCH attr=supportedControl conn=327 op=1 SEARCH RESULT tag=101 err=0 nentries=1 text= conn=327 op=2 SRCH base="o=example,c=xx" scope=2 deref=0 filter="(&(uid=jdoe)(objectClass=sambaSamAccount))" conn=327 op=2 SRCH attr=uid uidNumber gidNumber homeDirectory sambaPwdLastSet sambaPwdCanChange sambaPwdMustChange sambaLogonTime sambaLogoffTime sambaKickoffTime cn displayName sambaHomeDrive sambaHomePath sambaLogonScript sambaProfilePath description sambaUserWorkstations sambaSID sambaPrimaryGroupSID sambaLMPassword sambaNTPassword sambaDomainName objectClass sambaAcctFlags sambaMungedDial...
2005 Jan 26
2
ACL's for smbpasswd to work?
Samba experts, Thanks to advice from this list, I am finally able to get smbpasswd to change ldap passwords for the Samba LM/NT passwords. However, I had to give write access to sambaPwdLastSet and sambaPwdCanChange attributes as well. Other Samba attributes don't seem to need write access. I have found plenty of examples with people assigning an ACL for sambaLMPassword and sambaNTPassword, but I haven't found examples that included other attributes such as sambaPwdLastSet and sambaPwdCanChange....
2008 Feb 18
3
Problem with samba+openldap with regard changing passwords from windows
...P backend, domain logins and roaming profiles and everything is great - except for one thing. Noone can change their passwords from windows - trying to change your password results in windows telling you your not allowed to do that! I did smbldap-show alan and among other information the line: sambaPwdCanChange: 0 appeared. From my understanding if I do smbldap-usermod -A0 -B0 alan that line should then be changed to have a value of 1 allowing users to change passwords from their windows logins, however running the above command does not appear to be changing these values at all and thus im left with...
2004 Sep 22
1
3.0.7/LDAP/referrals...
..._with_state(698) rebindproc_connect_with_state: Rebinding as "cn=root,dc=hvcc,dc=edu" [2004/09/22 08:55:39, 1] passdb/pdb_ldap.c:ldapsam_modify_entry(1422) ldapsam_modify_entry: Failed to modify user dn= uid=CRK7$,ou=People,dc=hvcc,dc=edu with: No such attribute modify/delete: sambaPwdCanChange: no such attribute [2004/09/22 08:55:39, 0] passdb/pdb_ldap.c:ldapsam_update_sam_account(1622) ldapsam_update_sam_account: failed to modify user with uid = CRK7$, error: modify/delete: sambaPwdCanChange: no such attribute (Success) [2004/09/22 08:55:39, 5] rpc_parse/parse_prs.c:prs_debug(82) 00...
2007 Jul 17
2
[Urgent] Cannot make changes via pdbedit
...d to a date in the past. But for some reason it didn't work. If I run pdbedit -Lv -u jrolfe, I get: Password last set: Mon, 01 Jan 2007 03:00:00 EST Password can change: Mon, 08 Jan 2007 03:00:00 EST Password must change: never If I run ../smbldap-usershow jrolfe, I get: sambaPwdCanChange: 1183795200 sambaPwdLastSet: 1167638400 sambaPwdMustChange: 1167638400 The unix times converted to english are: Sat, 07 Jul 2007 08:00:00 GMT and Mon, 01 Jan 2007 08:00:00 GMT. So you can see that the dates do not match between pdbedit and smbldap-tools. This is really causing a problem...
2009 Aug 28
2
sambaPwdMustChange not synced on PDC from BDC
Hi I have a PDC/BDC samba/ldap environment. PDC: samba 3.0.24 slapd 2.3.30 BDC: samba 3.2.5 slapd 2.4.11 Ldap replication is working fine, but I have noticed two issues 1- when a windows user change password on BDC, sambaPwdMustChange and sambaPwdCanChange is not synced on PDC (using ldap passwd sync = yes and unix password sync = no) 2- when using 'net sam set pwdmustchange' on PDC, sambaPwdCanChange is not synced on BDC Anyone can point me what's wrong? About issue 1- , I can use unix password sync = yes and ldap passwd sync =...
2007 Aug 08
2
Enforcing Password Policies...
Dear Help, I'm currently running Samba with an LDAP passdb backend. I'm trying to figure out how to NOT allow a particular user to change their password (through Windows, or any interface). I've tried modifying the values for sambaPwdCanChange and sambaPwdMustChange for a particular user, but it seems like it only effects making them change their password, instead of whether or not they're ALLOWED to. Secondly, I've used pdbedit to edit the lockout policies when using a bad password ("lockout duration" = 30, "bad...
2008 Jan 25
1
Weird reproduceable delta after power failure - PDC
...After producing a power supply failure (stopping my Ubuntu and windows client by the stop button in vmware) and starting them up again i can see a delta in my ldap database: Before Power failure: ---------------------- uidNumber: 10000 sambaSID: S-1-5-21-2308582080-1758763575-3976210704-21000 sambaPwdCanChange: 1201212116 sambaNTPassword: C880093E1682DA079892FF7FF2AEA911 sambaPwdLastSet: 1201212116 After Power failure: ---------------------- uidNumber: 10005 sambaSID: S-1-5-21-2308582080-1758763575-3976210704-21010 sambaPwdCanChange: 1201260229 sambaNTPassword: 2446CE7E7D8B196756E40E80B5EC3A13 sambaPwdL...
2010 Nov 12
1
Samba and LDAP - which attributes are mandatory which optional
...d there where different attributes set than for adding users with the smbldap-useradd command. --- snip --- sambaAcctFlags: sambaHomeDrive: sambaHomePath: sambaKickoffTime: sambaLMPassword: sambaLogoffTime: sambaLogonScript: sambaLogonTime: sambaNTPassword: sambaPrimaryGroupSID: sambaProfilePath: sambaPwdCanChange: sambaPwdLastSet sambaPwdMustChange: --- snap --- Regards and Thanks for any help, G?tz -- G?tz Reinicke IT-Koordinator Tel. +49 7141 969 420 Fax +49 7141 969 55 420 E-Mail goetz.reinicke at filmakademie.de Filmakademie Baden-W?rttemberg GmbH Akademiehof 10 71638 Ludwigsburg www.filmakadem...
2005 Jun 04
3
smbldap-tools and joining workstation to domain
...puters,dc=IDEALX,dc=ORG objectClass: top objectClass: posixAccount objectClass: sambaSAMAccount cn: testhost3$ gidNumber: 553 homeDirectory: /dev/null loginShell: /bin/false uid: testhost3$ uidNumber: 1005 sambaPwdLastSet: 0 sambaLogonTime: 0 sambaLogoffTime: 2147483647 sambaKickoffTime: 2147483647 sambaPwdCanChange: 0 sambaPwdMustChange: 2147483647 description: Computer Account rid: 0 primaryGroupID: 0 lmPassword: 7582BF7F733351347D485E46C8E6306E ntPassword: 7582BF7F733351347D485E46C8E6306E acctFlags: [W ] Looking at smbldap-useradd script code I can see that sambaSAMAccount entrys are only added...
2005 Jun 10
2
samba ldap problem
...sambaAcctFlags: [U ] objectClass: account objectClass: sambaSamAccount sambaPwdMustChange: 2147483647 sambaLMPassword: 63D2114DE42F744B30A84C4AFE5AFFFF sambaNTPassword: 5460FB29D247C383F63E1E3A417FC39B sambaPasswordHistory: 00000000000000000000000000000000000000000000000000000000 00000000 sambaPwdCanChange: 1118395221 sambaPwdLastSet: 1118395221 # win2k$, Computers, example.com dn: uid=win2k$,ou=Computers,dc=example,dc=com uid: win2k$ sambaSID: S-1-5-21-3527759599-3696857034-3584459987-3022 sambaPrimaryGroupSID: S-1-5-21-3527759599-3696857034-3584459987-1201 objectClass: sambaSamAccount objectClass:...
2008 Sep 17
1
WG: Samba LDAP entries for Password Change
Hello, This must be set in LDAP: sambaPwdCanChange=1 ;or you will never be asked to change your password sambaPwdLastSet=0 sambaPwdMustChange=0; on my Suse this must be set too try it out for your machine And how you' ve been told the sambaMaxPwdAge must be set. Greetings Daniel -----Urspr?ngliche Nachricht----- Von: samba-bounces+mueller=tro...
2007 Aug 15
2
ldap passwd sync only
Hello I have exactly the same trouble as described here: http://www.nabble.com/ldap-passwd-sync-on-3.0.25a-tf4261008.html on samba-3.0.25b-2.fc7. When i set "ldap passwd sync" to "only" and I change password on some ldap samba user, password in attribute userPassword is never changed by samba daemon (to update NT and LM password I use smbk5pwd overlay). If i set pwd sync to
2009 Apr 15
2
samba machine accounts problem
...account ? objectClass: account sambaDomainName: srv01 displayName: bart sambaPrimaryGroupSID: S-1-5-21-3991578539-3149662252-1894531253-515 sambaSID: S-1-5-21-3991578539-3149662252-1894531253-101524 gidNumber: 515 loginShell: /bin/false homeDirectory: /dev/null uid: bart$ cn: bart uidNumber: 50262 sambaPwdCanChange: 1196710001 sambaPwdMustChange: 1204486001 sambaAcctFlags: [WX ] sambaPwdLastSet: 1238649797 # search result search: 2 result: 0 Success mfg sven
2004 Feb 04
2
SAMBA and LDAP
Hello.. When i use the command Smbpasswd ?a carguillo. It adds this entry in LDAP. # carguello,Personas,NOVA dn: uid=carguello,ou=Personas,o=NOVA uid: carguello sambaSID: S-1-5-21-2532083711-3846753250-2864659012-2328 sambaPrimaryGroupSID: S-1-5-21-2532083711-3846753250-2864659012-513 sambaPwdCanChange: 1075936258 sambaPwdMustChange: 2147483647 sambaLMPassword: B28511D60D92E507E917F8D6FA472D2C sambaNTPassword: E204FFF6A3487B4966896293ACC28B9B sambaPwdLastSet: 1075936258 sambaAcctFlags: [U ] objectClass: sambaSamAccount objectClass: account userPassword:: e1NTSEF9THJlaGg3MDNCTUJkR0h6QjVEN...
2008 Mar 17
1
Samba/Ldap problems with Versions > 3.0.24
...grading to versions greater than 3.0.24, there are problems with the timestamps which are correct set in the LDAP tree. Here are 2 examples: --------------------------------------------------- Example 1: Password can change=not empty LDAP: sambaPwdLastSet: 1205744729 sambaPwdMustChange: 1307828342 sambaPwdCanChange: 1192276342 sambaKickoffTime: 1228086000 Samba 3.0.24 -> correct: Logon time: Tue, 06 Feb 2007 16:07:05 CET Logoff time: Tue, 10 Feb 2004 09:18:42 CET Kickoff time: Mon, 01 Dec 2008 00:00:00 CET Password last set: Mon, 17 Mar 2008 10:05:29 CET Password can change:...
2018 Jul 04
5
classicupgrade questions
...", line 568, in upgrade_from_samba3     user = s3db.getsampwnam(username) The machine LDAP data: # pc0027$, machines, nspuh.cz dn: uid=pc0027$,ou=machines,dc=nspuh,dc=cz uid: pc0027$ objectClass: account objectClass: sambaSamAccount sambaPwdMustChange: 2147483647 sambaAcctFlags: [W          ] sambaPwdCanChange: 1158129830 sambaPwdLastSet: 1158129830 displayName: PC0027$ sambaSID: S-1-5-21-..numbers here...-45023 When I delete this machine from LDAP, the problem occurs with another computer.. and with another.. I finally deleted all machine/computer accounts from LDAP to be able to process users.  What...